Torva performs bounded technical checks. A high score means the checks performed found fewer issues; it does not establish that a network is secure or an organization is compliant.
Edge: your verified public domains
- Public DNS resolution and email authentication records: SPF, DMARC and DKIM selector checks. Unknown DKIM is reported as unknown.
- HTTPS certificate and negotiated TLS information, attempts to negotiate TLS 1.0/1.1, and HTTP-to-HTTPS redirects.
- Selected HTTP security headers, visible version banners, cookie flags and a limited directory-listing check.
- Daily and on-demand scans with history and change reporting.
Core: your approved internal ranges
- Reachability and a defined set of common TCP ports across approved RFC1918 IPv4 ranges, including routed VLANs the agent can reach.
- Service observations, selected web headers, TLS certificates and protocol negotiation checks.
- RDP network-level authentication negotiation evidence when the service responds.
- Unlimited devices per licensed site; multiple ranges can belong to one location.
Not currently checked
Authenticated operating-system patch inventory, CVE-database matching, Active Directory posture, SMB signing, broad UDP/SNMP discovery, full web application testing and organization-wide MFA enforcement are not included. Core does not currently scan IPv6 ranges. IP-based TLS observations do not provide full hostname/SNI coverage. Sleeping, filtered or unreachable devices may remain unassessed.
Regulatory and framework references
Select HIPAA, tax-preparation safeguards context or NIST CSF 2.0. A technical finding can relate to several cited references, but it is counted once in a unique-finding total. Applicability and supporting evidence still require review. NIST CSF is a framework, not a regulation. Source checks flag changes for review; they do not automatically approve revised legal interpretations.